Known Vulnerabilities for products from Iqonic

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Iqonic".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-25383 json Not Provided 2026-03-25 2026-03-25
CVE-2026-25034 json Not Provided 2026-03-25 2026-03-26
CVE-2025-52822 json Not Provided 2025-06-20 2026-04-01
CVE-2025-47533 json Not Provided 2025-05-07 2026-04-01
CVE-2025-47480 json Not Provided 2025-05-07 2026-04-01
CVE-2025-32254 json Not Provided 2025-04-04 2026-04-01
CVE-2025-26910 json Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBoo... Not Provided 2025-03-10 2026-04-01
CVE-2024-54280 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit ... Not Provided 2024-12-16 2026-04-01
CVE-2024-35659 json Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly... Not Provided 2024-06-08 2026-04-01
CVE-2023-41128 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 4.8 - MEDIUM 2023-11-30 2023-12-05
CVE-2023-2628 json The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX ac... 8.8 - HIGH 2023-06-27 2023-11-07
CVE-2023-2627 json The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowi... 4.3 - MEDIUM 2023-06-27 2023-11-07
CVE-2023-2624 json The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, le... 6.1 - MEDIUM 2023-06-27 2023-11-07
CVE-2023-2623 json The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data... 6.5 - MEDIUM 2023-06-27 2023-11-07
CVE-2022-0786 json The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements v... 9.8 - CRITICAL 2022-06-13 2022-06-17